1. Critical CVE-2022-29078: Server-Side Template Injection in EJS Library (ejs-2.7.4.tgz)
A critical-severity vulnerability, CVE-2022-29078, has been detected in the widely used EJS (Embedded JavaScript templates) library, specifically version 2.7.4. This flaw allows for server-side template injection, enabling an attacker to execute arbitrary operating system commands on the host server. The vulnerability ...